CVE-2022-39177: High severity BlueZ BlueZ vulnerability
Published Sep 2, 2022
·Updated
BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.
Affected Software
4 affected components
BlueZ BlueZ<5.59
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Sep 2, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-39177?
CVE-2022-39177 is a vulnerability in BlueZ before 5.59 that allows physically proximate attackers to cause a denial of service.
2
How does CVE-2022-39177 impact BlueZ?
CVE-2022-39177 can be exploited by physically proximate attackers to cause a denial of service on BlueZ.
3
What is the severity of CVE-2022-39177?
CVE-2022-39177 has a severity rating of 8.8 (high).
4
Which software versions are affected by CVE-2022-39177?
BlueZ versions before 5.59 are affected by CVE-2022-39177. Specifically, it affects BlueZ on Ubuntu Linux 18.04 LTS, Ubuntu Linux 20.04 LTS, and Debian Linux 10.0.
5
How can the CVE-2022-39177 vulnerability be mitigated?
To mitigate the CVE-2022-39177 vulnerability, it is recommended to update BlueZ to version 5.59 or later.